← The Diary

August 1, 2026

Human in the Loop, On the Loop, or Out of the Loop: Which One Each of Your Workflows Needs

human in the loopai policyworkflow designsmall businessai governance

Human in the loop means a person approves every output before it goes anywhere. On the loop means the work runs on its own and a person watches, able to step in. Out of the loop means it runs unattended. Most small businesses default to one setting for everything. The useful move is deciding per workflow, because the cost of being wrong is different for each one.

The three levels, in plain terms

You will see "human in the loop" used as though it means one thing. It does not. There are three distinct arrangements, and picking the wrong one is expensive in two different directions.

In the loop

A person reviews and approves each output before anything happens with it. The AI drafts, a human signs off, and only then does it send, post, publish, or book. Nothing reaches a customer without someone seeing it first.

Costs you: speed. Every item waits for a person. Buys you: nothing goes out wrong.

On the loop

The work runs on its own. A person monitors it and can intervene. The AI handles the volume. A human watches the queue, spots the odd one, and pulls it back. You are not approving each item, you are supervising the pattern.

Costs you: you will occasionally catch something after it has gone out, not before. Buys you: most of the speed, most of the safety.

Out of the loop

It runs unattended. Nobody looks unless something breaks.

Costs you: you find out about failures from your customers. Buys you: it scales without you.

The two ways businesses get this wrong

Too much oversight. A team puts a human approval step on everything, then quietly abandons the whole system three weeks later because approving 200 drafts a week is worse than writing 20 emails by hand. The automation was fine. The oversight setting was wrong.

Too little oversight. A team runs everything unattended because it worked in testing, and then a customer gets a message with the wrong name, the wrong price, or the wrong tone at the wrong moment. The recovery costs more than the automation ever saved.

Both failures come from the same mistake: treating oversight as one dial for the whole business instead of a per-workflow decision.

How to decide, per workflow

Three questions. They take about a minute each.

1. What happens if this goes out wrong? If the answer involves a customer, money, a legal obligation, or someone's feelings, it needs a person. If the answer is "we fix it and nobody notices," it does not.

2. How often does it run? Something that runs twice a week can have a human approve every instance forever. Something that runs two hundred times a week cannot, and pretending otherwise is how systems get abandoned.

3. Could a person tell it was wrong by looking at it? This is the one people skip. If the error would be obvious at a glance, a monitoring step catches it. If the error is a plausible-looking wrong number buried in a paragraph, monitoring will not catch it and you need real review, or you need to not automate that piece at all.

Where common small-business workflows land

Starting points, not rules. Your business may have a good reason to move any of these.

Notice the pattern: the level tracks the blast radius, not the difficulty. Summarizing a fifty-page contract is technically harder than writing an appointment reminder, and it needs less oversight, because nobody outside the building sees the summary.

Three things that actually happen

The confident wrong detail. An AI drafts a polished, professional email with one incorrect figure in the third paragraph. Everything around it reads perfectly, which is exactly why nobody catches it on a skim. This is the argument for in-the-loop on anything with a number in it.

The technically correct, humanly wrong message. An automation flags a teammate's overdue tasks and sends the nudge. The teammate has been out with a family emergency. The system did its job. A person would have known not to. Automation reads the signal, people read the situation.

The abandoned approval queue. A business puts review on everything, and within a month the approvals are rubber-stamped without reading, because 200 items a week is not a thing a person does carefully. That is worse than no review, because now there is a false sense of oversight. If you cannot review it properly, move it to on-the-loop and design the monitoring instead.

What "on the loop" actually looks like

This is the level most businesses should be using more, and the one people have the least concrete picture of. It is not "we hope someone notices." It means:

Without those five, "on the loop" is just "out of the loop" with extra confidence.

The short version

You do not need a policy document to start. You need one pass through your repeated work, sorting each item into three buckets, and a written note of why.

Most businesses find the same thing when they do it: a few workflows were being guarded that did not need it, one or two were running unattended that should not have been, and the loud, obvious automation everyone argues about was never the risky one.

Where this goes next

Sorting your own workflows into these three levels is exactly what an AI Readiness Assessment does, with your actual processes rather than a generic list. You finish with a written roadmap naming which workflows need approval, which need monitoring, and which can run on their own, plus what it would take to build them.

— Diary of an AI Practitioner —